Splunk Engineer-Core Certified Consultant jobs in United States
cer-icon
Apply on Employer Site
company-logo

True Zero Technologies · 1 month ago

Splunk Engineer-Core Certified Consultant

True Zero Technologies is a veteran-owned small business dedicated to enabling people and technology to improve organizational outcomes. They are seeking a Splunk Engineer-Core Certified Consultant to develop and implement RBA strategies, create dashboards, and collaborate with data sources for effective analysis within RBA.

Information ServicesInformation Technology

Responsibilities

Develop and implement RBA strategies within Splunk ES to reduce alert noise and focus on high-fidelity alerts
Build and implement actionable alerts, workflow actions, risk incident rules, and risk scores
Design custom dashboards to visualize risk scores and provide context for analysts
Use Splunk's capabilities to correlate disparate events to identify patterns of risky behavior
Develop custom machine learning (ML) models to augment alerting and create automated workflows to improve efficiency
Develop advanced security content, including dashboards, reports, and alerts, to highlight risk details, health analysis, and risk suppression specific to RBA environments
Collaborate with application and system owners to onboard new data sources (e.g., from Windows, Linux, cloud services like AWS/Azure) and ensure proper parsing and enrichment for effective analysis within RBA
Correlate various data sources, such as logs from operating systems, applications, and cloud providers, into Splunk to feed RBA models

Qualification

Splunk administrationSearch Processing Language (SPL)Security operationsPythonPowerShellBashRBA strategiesSplunk certificationsAgile collaboration

Required

Core Certified Consultant is a requirement
Deep technical expertise in Splunk administration, architecture, and Search Processing Language (SPL)
Strong understanding of security operations, threat detection, incident response, and security frameworks (e.g., NIST RMF)
Proficiency in scripting languages like Python, PowerShell, or Bash for automation and data analysis
Willingness to collaborate within an agile environment

Preferred

Preferred relevant Splunk certifications are a plus such as: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Certified Architect, Splunk ES

Benefits

Best in class medical coverage
100% of medical premiums covered by True Zero
Company wide new business incentive programs
Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)
3 weeks of PTO starting + 11 Paid Holidays Annually
401k Program with 100% company match on the first 4%
Monthly reimbursement of Cell Phone and Home Internet costs
Paternity/Maternity Leave
Investment in training and certifications to broaden and deepen your technical skills

Company

True Zero Technologies

twittertwitter
company-logo
True Zero Technologies, a veteran-owned small business.

Funding

Current Stage
Growth Stage

Leadership Team

leader-logo
Carl Salzano
Chief Executive Officer
linkedin
leader-logo
Jonathan Cooper
Chief Technology Officer
linkedin
Company data provided by crunchbase